What Is GDPR? Complete Guide to EU Data Protection (2026)

The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's binding data protection law, enforceable since May 25, 2018. It grants individuals rights over their personal data, places compliance obligations on organizations that handle it, and reaches organizations with no EU establishment that offer goods or services to people who are in the EU, or that monitor their behavior as far as that behavior takes place in the EU.
The General Data Protection Regulation, universally known as the GDPR, is the world's most influential data protection law. Published as Regulation (EU) 2016/679 in the Official Journal of the European Union on May 4, 2016, it became enforceable on May 25, 2018, after a two-year transition period. It applies directly in every EU member state and, through Article 3, reaches organizations based anywhere in the world that process the personal data of people located in the EU.
This guide explains the GDPR from the ground up: its origins, territorial scope, seven core principles, key definitions, the six lawful bases for processing, an overview of data subject rights, who enforces it, what penalties look like, how it relates to national law, and the latest 2024-2026 developments. For detailed treatment of specific topics, use the sibling guides linked throughout.
For the broader EU legal context, see our EU data privacy laws overview.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified data protection attorney or privacy professional for advice specific to your situation.
Quick Answer: What Is the GDPR?
The GDPR is a directly applicable EU regulation that sets uniform rules for collecting, storing, using, and sharing the personal data of individuals located in the EU and European Economic Area. "Regulation" is the key word: unlike an EU directive, a regulation does not require member states to pass implementing legislation. It became binding law automatically in every EU member state on the same day. There were 28 member states at the time, including the United Kingdom, which has since left the EU; the regulation applies today across the 27 member states.
At its core, the GDPR does three things. It gives individuals (called "data subjects") enforceable rights over their personal data. It places obligations on the organizations (called "controllers" and "processors") that handle that data. And it establishes independent supervisory authorities in every member state to investigate complaints and levy fines when things go wrong.
The GDPR replaced Directive 95/46/EC, the 1995 Data Protection Directive, which had governed EU data protection for over two decades.

History and Purpose
The 1995 Data Protection Directive
The EU's first major data protection framework was Directive 95/46/EC, adopted in October 1995. A directive does not apply directly; each member state had to pass its own national implementing law. The result was a patchwork of 28 different national statutes. Businesses operating across Europe had to navigate a different compliance regime in each country.
The directive worked tolerably for the dial-up internet era but grew increasingly inadequate as social media platforms, cloud services, and smartphones generated personal data on an unprecedented scale through the 2000s and early 2010s.
From Proposal to Adoption
The European Data Protection Supervisor (EDPS) documented that the European Commission first proposed replacing the directive with a regulation in January 2012. Choosing a regulation rather than a new directive solved the patchwork problem: a single set of rules would apply uniformly across all member states.
Negotiations between the European Parliament, the Council of the European Union, and the Commission ran for four years and involved more than 3,000 parliamentary amendments. The Council adopted its position on April 8, 2016. The European Parliament approved the final text on April 14, 2016. The regulation was published in the Official Journal on May 4, 2016, with May 25, 2018, set as the enforcement date, giving organizations two years to prepare.
Post-Enforcement Evolution
The GDPR did not freeze data protection law in 2018. The European Data Protection Board (EDPB) has published dozens of guidelines interpreting specific provisions. Courts across Europe have issued landmark rulings on consent, legitimate interests, and international data transfers. DLA Piper's GDPR Fines and Data Breach Survey of January 2026 put cumulative fines at about EUR 7.1 billion for the period from 25 May 2018 to 10 January 2026, with roughly EUR 1.2 billion in 2025. The CMS GDPR Enforcement Tracker, which counts a narrower set of publicly reported actions, records about EUR 6.31 billion across 3,228 actions.
April 2026 marked ten years since the GDPR's adoption in April 2016. In its anniversary statement the EDPB described the regulation as the first comprehensive data protection framework spanning an entire continent, and said its impact has extended far beyond Europe's borders, inspiring similar frameworks across the globe.
Territorial Scope: Who Must Comply? (Article 3)
Article 3 of the GDPR is unusually broad for a national or regional law. It establishes two main criteria for applicability.
The Establishment Criterion (Article 3(1))
The GDPR applies to any controller or processor that processes personal data "in the context of the activities of an establishment" in the EU. Establishment does not require formal incorporation; a branch, subsidiary, or stable arrangement of any kind qualifies.
Critically, processing does not need to occur on EU soil. A company headquartered in Berlin that processes customer data on servers in the United States is still subject to the GDPR because processing occurs in the context of its EU establishment.
The Targeting Criterion (Article 3(2))
Organizations with no EU establishment must still comply if they:
- Offer goods or services to individuals in the EU, whether or not payment is required; or
- Monitor the behavior of individuals located in the EU, as far as that behavior takes place within the Union, including through website analytics, behavioral advertising, location tracking, and cookie-based profiling.
The EDPB Guidelines 3/2018 on territorial scope clarify that a website merely being accessible from the EU is not sufficient. There must be evidence of intent to target people in the EU: accepting euros, providing content in EU languages, or expressly referencing EU customers are all indicators.
Article 3(2) is not a residency test. It reaches data subjects who are in the Union, and Recital 14 states that the protection applies to natural persons whatever their nationality or place of residence. A non-EU national visiting the EU is therefore covered, while an EU citizen living or travelling outside the Union may fall outside Article 3(2) altogether.
The EU Representative Requirement (Article 27)
Non-EU organizations subject to the GDPR by virtue of the targeting criterion must designate a written representative within the EU. This representative acts as the point of contact for supervisory authorities and data subjects.
The duty is not absolute. Article 27(2) exempts processing that is occasional, does not include large-scale processing of the special categories in Article 9(1) or of criminal-conviction data under Article 10, and is unlikely to result in a risk to the rights and freedoms of individuals. It also exempts public authorities and bodies.
Where a representative is required, Article 27(3) says it must be established in one of the member states where the affected data subjects are.

The Seven Data Protection Principles (Article 5)
Article 5 of the GDPR lays down seven principles that apply to every processing activity. Violating them triggers the higher tier of fines (up to EUR 20 million or 4% of global turnover). The accountability principle in Article 5(2) places the burden of proof on the organization to demonstrate compliance with all seven.
1. Lawfulness, Fairness, and Transparency
Processing must have a valid legal basis under Article 6. It must be conducted in ways that people would reasonably expect and not cause unjustified harm. Organizations must clearly tell people what happens to their data through accessible privacy notices.
2. Purpose Limitation
Personal data may only be collected for specified, explicit, and legitimate purposes and may not be further processed in a manner incompatible with those original purposes. Collecting email addresses for order confirmations and later using them for marketing without a separate legal basis violates this principle. Limited exceptions exist for archiving, scientific research, and statistical purposes.
3. Data Minimization
Only personal data that is adequate, relevant, and limited to what is strictly necessary for the stated purpose may be processed. Organizations should not collect data "just in case" it becomes useful later.
4. Accuracy
Personal data must be accurate and kept up to date. Organizations must take every reasonable step to erase or correct inaccurate data without delay. The ICO guidance on data protection principles notes that accuracy means the data must not be misleading in context, not merely technically correct.
5. Storage Limitation
Data must be held in identifiable form only for as long as necessary for the processing purpose. Once the purpose is fulfilled, the organization must delete or anonymize the data. Retention schedules must be documented; indefinite storage is not permitted.
6. Integrity and Confidentiality (Security)
Personal data must be processed with appropriate technical and organizational security measures to protect it against unauthorized access, accidental loss, destruction, or damage. This principle underpins the breach notification obligations in Articles 33 and 34.
7. Accountability
The controller is responsible for, and must be able to demonstrate, compliance with all six principles above. This is an active obligation: maintaining records of processing activities, conducting data protection impact assessments where required, appointing a Data Protection Officer where mandated, and making compliance evidence available to supervisory authorities.
Key Definitions (Article 4)
Article 4 of the GDPR contains 26 definitions. The six that appear throughout every compliance analysis are:
Personal Data
Any information relating to an identified or identifiable natural person (the "data subject"). The definition is intentionally broad and technology-neutral. It covers names, email addresses, phone numbers, IP addresses, cookie identifiers, location data, genetic data, biometric data, photographs, and any combination of data that could directly or indirectly identify someone.
The European Commission emphasizes that the GDPR applies whether data is stored digitally, on paper, or captured through video surveillance.
Processing
"Processing" covers virtually any operation performed on personal data: collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure, or destruction. The definition is deliberately expansive; if you handle personal data in any way, you are processing it.
Controller
The data controller is the natural or legal person, public authority, agency, or other body that determines the purposes and means of processing. Controllers decide why data is collected and how it will be used. They bear primary GDPR compliance responsibility.
Processor
A data processor processes personal data on behalf of, and under the instructions of, a controller. A cloud hosting company that stores a retailer's customer database is acting as a processor. Processors must follow the controller's instructions, implement appropriate security, and enter into a written data processing agreement under Article 28. EDPB Guidelines 07/2020 provide detailed guidance on determining roles.
Data Subject
The natural person whose personal data is being processed. Data subjects are the rights-holders under Chapter III of the GDPR.
Special Categories of Personal Data
Article 9 identifies categories of data that are especially sensitive and warrant extra protection: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, and data about sex life or sexual orientation. Processing these categories is prohibited by default; only the specific exceptions listed in Article 9(2) permit it.
The Six Lawful Bases for Processing (Article 6)
Every act of processing must rest on one of the six lawful bases set out in Article 6. Controllers must identify and document the applicable basis before processing begins. Bases cannot be switched after the fact.
| Lawful Basis | When It Applies | Typical Example |
|---|---|---|
| Consent | Data subject gives a freely given, specific, informed, and unambiguous indication of agreement | Newsletter signup with an explicit opt-in checkbox |
| Contractual Necessity | Processing is necessary to perform a contract with the data subject, or to take pre-contractual steps at their request | Using a shipping address to fulfill an online order |
| Legal Obligation | Processing is required to comply with a legal obligation under EU or member state law | Retaining payroll records for tax purposes |
| Vital Interests | Processing is necessary to protect the life of the data subject or another person | Sharing medical data in an emergency |
| Public Interest / Official Authority | Processing is necessary for a task carried out in the public interest or in the exercise of official authority | Public health surveillance by a government agency |
| Legitimate Interests | Processing is necessary for the controller's (or a third party's) legitimate interests, which are not overridden by the data subject's interests or fundamental rights | Fraud prevention, network security, direct marketing (with care) |
Consent is often misidentified as the default basis. The EDPB Guidelines 1/2024 on legitimate interests clarify that legitimate interests requires a balancing test and cannot be used for processing that clearly overrides individual rights.
For detailed guidance on when consent is needed and what makes it valid, see our guide to GDPR consent requirements.
Data Subject Rights: An Overview (Chapter III)
Chapter III of the GDPR grants eight categories of rights to data subjects. Controllers must respond to rights requests without undue delay and within one month (extendable by two further months for complex requests). Responses must be free of charge, with one exception: under Article 12(5) a controller may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, and the controller bears the burden of demonstrating that.
| Right | Article | What It Means |
|---|---|---|
| Right to be informed | Arts. 13, 14 | Receive clear information about processing through privacy notices |
| Right of access | Art. 15 | Obtain confirmation of processing and a copy of personal data held |
| Right to rectification | Art. 16 | Have inaccurate or incomplete data corrected |
| Right to erasure ("right to be forgotten") | Art. 17 | Have data deleted when no longer needed, consent is withdrawn, or processing was unlawful |
| Right to restriction | Art. 18 | Limit processing in defined circumstances while a dispute is resolved |
| Right to data portability | Art. 20 | Receive the personal data you provided, in a structured, commonly used and machine-readable format, and transmit it to another controller. Applies only where the processing rests on consent or on a contract and is carried out by automated means |
| Right to object | Art. 21 | Object to processing based on legitimate interests or direct marketing |
| Rights related to automated decision-making | Art. 22 | Not be subject solely to automated decisions that produce significant legal or similar effects |
None of these rights is absolute. The GDPR sets out specific grounds on which controllers may refuse or limit requests. For a full treatment of each right and how organizations must respond, see our guide to GDPR data subject rights.
Enforcement: How the GDPR Is Policed

National Supervisory Authorities (DPAs)
Each EU member state has at least one independent Data Protection Authority. DPAs have three categories of powers under Article 58:
- Investigative powers: audits, access to premises, ordering information to be provided, and carrying out data protection audits.
- Corrective powers: warnings, reprimands, orders to comply, temporary or permanent bans on processing, and administrative fines.
- Authorization and advisory powers: approving binding corporate rules, issuing opinions, authorizing standard contractual clauses.
Well-known DPAs include Ireland's Data Protection Commission (DPC), France's CNIL, Germany's multiple Landesbeauftragten, Italy's Garante, and Spain's AEPD.
The European Data Protection Board (EDPB)
The EDPB is the independent EU body comprising all national DPAs and the European Data Protection Supervisor. It replaced the Article 29 Working Party when the GDPR took effect. The EDPB issues binding decisions in cross-border disputes, publishes interpretive guidelines, and coordinates enforcement across member states.
The One-Stop-Shop Mechanism
For organizations operating across multiple EU member states, the GDPR's one-stop-shop mechanism designates a single "lead supervisory authority": typically the DPA in the member state of the organization's main EU establishment. Other "concerned" DPAs can raise objections to draft decisions, and unresolved disputes are escalated to the EDPB for a binding decision.
Ireland's DPC has emerged as the dominant enforcer by monetary value because so many large technology companies (Meta, Google, Apple, TikTok, LinkedIn, X) have their European headquarters in Dublin. Our guide explains how to make a GDPR complaint to Ireland's Data Protection Commission.
Penalties (Articles 83 and 84)
The GDPR establishes two tiers of administrative fines:
Lower tier (Article 83(4)): up to EUR 10 million or 2% of global annual turnover, whichever is higher. This applies to violations of controller and processor obligations under Articles 8, 11, 25-39, 42, and 43 (including DPO requirements, data protection by design, and breach notification).
Upper tier (Article 83(5)): up to EUR 20 million or 4% of global annual turnover, whichever is higher. This applies to violations of the basic principles (Article 5), lawful bases (Article 6), consent conditions (Article 7), special categories rules (Article 9), data subject rights (Chapter III), and international transfer rules (Chapter V).
Member states may also impose additional penalties under Article 84, including criminal sanctions.
Notable enforcement examples:
- Ireland's DPC fined TikTok EUR 530 million in April 2025 over transfers of EEA user data to China. The total splits into EUR 485 million under Article 46(1), for failing to verify, guarantee and demonstrate that the transferred data received protection essentially equivalent to EU standards, and EUR 45 million under Article 13(1)(f) for transparency failures, with an order to bring the processing into compliance within six months.
- Ireland's DPC fined Meta EUR 1.2 billion in 2023 for unlawful data transfers to the United States via standard contractual clauses.
- Ireland's DPC fined Meta EUR 251 million in December 2024 for breach notification and data security failures related to the 2018 "View As" vulnerability.
- LinkedIn was fined EUR 310 million in 2024 for using behavioral advertising without a valid lawful basis.
Several of these decisions are still being litigated. The DPC's own judgments index lists 2026 judgments in TikTok Technology Limited v DPC in both the High Court and the Supreme Court, and in Meta Platforms Ireland Ltd v DPC in the High Court. Treat the figures above as decisions taken, not as outcomes finally settled by the courts.
DLA Piper's January 2026 survey put cumulative GDPR fines at about EUR 7.1 billion to 10 January 2026. For the complete breakdown of how fines are calculated and the full list of major enforcement actions, see our guide to GDPR fines and penalties.
GDPR and National Implementing Laws
Despite being a directly applicable regulation, the GDPR includes more than 50 opening clauses that permit or require member states to add, restrict, or adapt specific provisions under national law. The result is that GDPR compliance in Germany is not identical to GDPR compliance in France or Ireland.
Common areas of national variation include:
Age of consent for children's data. Article 8 sets the default at 16 years but allows member states to lower it to a minimum of 13. Current member states sit at different points in that band. Ireland kept 16, in section 31 of its Data Protection Act 2018. Spain set 14, in Article 7 of Organic Law 3/2018.
Special categories of data. Article 9(4) allows member states to impose additional conditions on processing health data, genetic data, and biometric data for identification purposes.
Employment data. Article 88 permits member states to adopt specific rules for employee data, including pre-employment screening and workplace monitoring.
Freedom of expression and journalism. Article 85 requires member states to reconcile data protection with freedom of expression, including for journalistic, academic, and artistic purposes.
Criminal convictions data. Article 10 leaves to member states the conditions under which records of criminal offenses may be processed by private parties.
Organizations operating across multiple member states need to verify not only the GDPR itself but the applicable national implementation law in each relevant state.
Recent Developments: 2024 to 2026
GDPR Procedural Regulation (Regulation (EU) 2025/2518)
One persistent criticism of the GDPR was that cross-border enforcement cases took too long. The one-stop-shop mechanism required extensive cooperation between the lead DPA and concerned DPAs, and there were no binding deadlines.
The EU addressed this with Regulation (EU) 2025/2518, the GDPR Procedural Regulation. Published in the Official Journal on December 12, 2025, it entered into force on January 1, 2026, and will apply from April 2, 2027 (with transitional rules protecting ongoing investigations).
Key changes:
- Binding 15-month deadline for lead DPA investigations, extendable by 12 months for complex cases.
- Standardized procedures for complainants and parties under investigation.
- Greater transparency obligations on enforcement timelines.
- Clarified participation rights for complainants during the enforcement process.
This regulation does not alter substantive GDPR obligations; it governs how DPAs coordinate and what procedural rights parties have.
The Digital Omnibus Proposal (November 2025)
On November 19, 2025, the European Commission tabled the Digital Omnibus as two separate legislative proposals, and they have moved at very different speeds.
The AI limb has been adopted. It is now Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It does not amend the GDPR.
The data limb, COM(2025) 837, is the one that would amend the GDPR, alongside the Data Act, the ePrivacy Directive, NIS 2, and others. It is still only a proposal. As of September 2026 the European Parliament's Legislative Observatory records its status as awaiting committee decision, with committee referral announced on 19 January 2026. It has not reached trilogue, and the GDPR text is unchanged.
Key proposed GDPR amendments include:
- Amending Article 12(5) to add an abuse-of-rights ground on which a controller may charge a fee for, or refuse, an Article 15 access request.
- Amending Article 13 by replacing paragraph 4 and adding a paragraph 5, which would switch off the transparency duties in defined low-intensity relationships and in some scientific research.
- Adjusting the purpose-limitation rule in Article 5(1)(b).
- Amending Article 33(1) so that a personal data breach is notified only where it is likely to result in a high risk, within 96 hours rather than 72, and through the single entry point established under Article 23a of Directive (EU) 2022/2555 (NIS 2).
- Refining Article 22 on automated decision-making.
- Amending the definitions in Article 4 and the special-categories rule in Article 9, and adding new Articles 88a to 88c.
Two points often reported about this proposal are wrong. It creates no new Article 33a; the single entry point comes from the NIS 2 Directive. And it does not touch Article 14, Article 15, or Article 30.
The EDPB and EDPS issued a joint opinion in early 2026 supporting certain simplification elements but raising serious concerns about proposed changes to the definition of personal data, which they argued went beyond established CJEU case law and would significantly narrow the concept. The current GDPR text remains in force until any amendments complete the legislative process and are formally published.
Record-Keeping Under Article 30 Sits in a Different Package
The proposal to relax the Article 30(5) record-keeping derogation is not part of the Digital Omnibus. It belongs to Omnibus IV, COM(2025) 501 of 21 May 2025, procedure 2025/0130(COD).
The provisional agreement resulting from interinstitutional negotiations, PE790.249 of 26 June 2026, would replace Article 30(5) so that the records duty does not apply to an enterprise or organisation employing fewer than 1,000 persons, unless and to the extent that a specific processing activity is likely to result in a high risk to rights and freedoms within the meaning of Article 35, and in any event where that activity is a core activity requiring a data protection officer under Article 37(1), point (b) or (c). Committee approval followed on 2 July 2026, and the indicative plenary date is 23 November 2026.
That text is not law yet. The threshold in force today is still the original one: fewer than 250 persons.
EU AI Act and GDPR
The EU AI Act entered into force on 1 August 2024, and its phased timeline now runs to 2028 rather than 2026. Chapters I and II, including the first prohibited practices, applied from 2 February 2025, the general-purpose AI obligations from 2 August 2025, and the general date of application is 2 August 2026. Regulation (EU) 2026/1744 then moved the high-risk obligations in Chapter III, Sections 1 to 3, to 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those classified under Article 6(1) and Annex I. It also set the newly inserted Article 5 prohibitions to apply from 2 December 2026. The EDPB has confirmed that processing personal data to develop or deploy AI systems is subject to GDPR obligations, and the EDPB is working with the Commission's AI Office on joint guidelines on the interplay between the AI Act and GDPR, expected for adoption in 2026. The core principle is straightforward: AI Act compliance does not substitute for GDPR compliance.
The GDPR's Global Influence
Since 2018, the GDPR has shaped privacy legislation well beyond Europe. Brazil's Lei Geral de Protecao de Dados (LGPD), Japan's amended Act on the Protection of Personal Information (APPI), South Korea's Personal Information Protection Act (PIPA), and India's Digital Personal Data Protection Act of 2023 all incorporate GDPR-derived concepts. California's CCPA and CPRA introduced GDPR-style data subject rights into US law.
The European Commission's adequacy framework reinforces this influence: countries seeking to receive personal data freely from the EU must demonstrate protections "essentially equivalent" to the GDPR, effectively setting GDPR compliance as a global benchmark.
Frequently Asked Questions
What does GDPR stand for?
GDPR stands for General Data Protection Regulation. It is Regulation (EU) 2016/679 of the European Parliament and of the Council, adopted on April 14, 2016, and enforceable since May 25, 2018. The regulation standardizes data protection law across all EU member states and the European Economic Area, replacing the 1995 Data Protection Directive.
Does the GDPR apply outside of Europe?
Yes. Article 3(2) gives the GDPR extraterritorial reach. An organization with no establishment in the EU must comply where it offers goods or services to people who are in the EU, or monitors their behavior as far as that behavior takes place within the Union, for example through website analytics, behavioral advertising, or tracking. Nationality and place of residence are irrelevant under Recital 14, so a visitor physically in the EU is covered, while an EU citizen living outside the Union may not be. A company in the United States, Canada, or Japan is subject to the GDPR when it processes the personal data of people in the EU in those contexts.
What are the seven principles of the GDPR?
The seven principles under Article 5 are: (1) lawfulness, fairness, and transparency; (2) purpose limitation; (3) data minimization; (4) accuracy; (5) storage limitation; (6) integrity and confidentiality (security); and (7) accountability. These principles apply to all processing of personal data. The accountability principle places the burden on the controller to demonstrate compliance with the other six.
What is the difference between a data controller and a data processor?
A controller decides the purposes and means of processing personal data and bears primary GDPR compliance responsibility. A processor handles personal data on behalf of the controller, following the controller's instructions. For example, a retailer (controller) that uses a cloud hosting provider (processor) to store customer data. Controllers and processors must enter into a written data processing agreement under Article 28.
What are the six lawful bases for processing?
Article 6 sets out six lawful bases: (1) consent of the data subject; (2) contractual necessity; (3) compliance with a legal obligation; (4) protection of vital interests; (5) performance of a task in the public interest or exercise of official authority; and (6) legitimate interests of the controller or a third party. Every processing activity must be justified under one of these bases before processing begins.
What are the maximum GDPR fines?
The highest tier of GDPR fines is EUR 20 million or 4% of total worldwide annual turnover from the preceding financial year, whichever is higher. This applies to violations of core principles, lawful bases, data subject rights, and international transfer rules. A lower tier of EUR 10 million or 2% applies to more procedural violations. As of September 2026 the largest single GDPR fine on record is EUR 1.2 billion, issued to Meta by Ireland's DPC in 2023 for unlawful data transfers, and that decision is still the subject of court proceedings.
What is the GDPR Procedural Regulation?
Regulation (EU) 2025/2518, known as the GDPR Procedural Regulation, was published in December 2025 and entered into force on January 1, 2026, with application from April 2, 2027. It introduces binding deadlines for cross-border enforcement cases (a 15-month investigation window, extendable by 12 months), standardized procedural rights for complainants and parties under investigation, and improved transparency. It does not change the substantive obligations in the GDPR itself.
What is the EU Digital Omnibus and how does it affect the GDPR?
The Commission tabled the Digital Omnibus on November 19, 2025 as two proposals. The AI limb was adopted as Regulation (EU) 2026/1744 and has been in force since 27 July 2026; it does not amend the GDPR. The data limb, COM(2025) 837, is the one that would amend the GDPR, and it is still a proposal: as of September 2026 the European Parliament Legislative Observatory lists it as awaiting committee decision. Its proposed GDPR changes include an abuse-of-rights ground in Article 12(5), narrower transparency duties in Article 13, breach notification in Article 33(1) only for high-risk breaches and within 96 hours through the NIS 2 single entry point, and changes to Articles 4, 5(1)(b), 9 and 22. The record-keeping relief for smaller organizations sits in a separate package, Omnibus IV, which is also not yet adopted. The current GDPR text remains in force.
When did the GDPR take effect?
The GDPR was adopted on April 14, 2016, published on May 4, 2016, and took effect on May 25, 2018, after a two-year transition period. It replaced the 1995 Data Protection Directive (Directive 95/46/EC). The GDPR was adopted on April 14, 2016 and became applicable on May 25, 2018. May 25, 2026 marked the eighth anniversary of the GDPR becoming applicable.
Updates
Corrected the Article 3(2) territorial-scope test to the statutory standard of people who are in the EU, restated the Digital Omnibus and EU AI Act items against the current EU texts, moved the Article 30 record-keeping change to Omnibus IV where it belongs, added the Article 27(2) representative exemptions and the Article 20 and Article 12(5) limits, attributed the cumulative-fines figure to its source, and replaced two dead official links
Expanded from 2,850 to approximately 4,800 words; added dedicated sections on data subject rights overview (Chapter III table), GDPR and national implementing laws, and Recent Developments (2024-2026) covering the GDPR Procedural Regulation (Regulation (EU) 2025/2518), the Digital Omnibus proposal (proposal only, not enacted), and EU AI Act interplay; updated enforcement statistics through early 2026 (EUR 7.1 billion cumulative, EUR 530M TikTok fine, EDPB 10th anniversary); added new FAQ entries; expanded citations to 23 sources. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log
Initial publication
Sources and References
- GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
- Directive 95/46/EC — 1995 Data Protection Directive(eur-lex.europa.eu).gov
- GDPR Consolidated Text (EUR-Lex)(eur-lex.europa.eu).gov
- European Data Protection Board (EDPB)(edpb.europa.eu).gov
- EDPB Guidelines 3/2018 on Territorial Scope (Article 3)(edpb.europa.eu).gov
- EDPB SME Guide - Data Protection Basics and the Key GDPR Principles(edpb.europa.eu).gov
- EDPB Guidelines 1/2024 on Legitimate Interests (Article 6(1)(f))(edpb.europa.eu).gov
- EDPB Guidelines 07/2020 — Controller and Processor(edpb.europa.eu).gov
- EDPB SME Guide — Data Controller vs Data Processor(edpb.europa.eu).gov
- EDPB SME Guide — Respecting Individuals Rights(edpb.europa.eu).gov
- EDPB and EDPS Joint Opinion on Digital Omnibus (2026)(edpb.europa.eu).gov
- EDPB — Marking 10 Years of the GDPR (2026)(edpb.europa.eu).gov
- EDPS — History of the GDPR(edps.europa.eu).gov
- European Commission — Principles of the GDPR(commission.europa.eu).gov
- European Commission - Application of the GDPR (roles of controller and processor)(commission.europa.eu).gov
- European Commission — Data Protection Explained(commission.europa.eu).gov
- European Commission — Adequacy Decisions(commission.europa.eu).gov
- European Commission — Data Protection in the EU(commission.europa.eu).gov
- ICO — Guide to the Data Protection Principles(ico.org.uk).gov
- Article 3 GDPR — Territorial Scope(gdpr-info.eu)
- Article 5 GDPR — Principles(gdpr-info.eu)
- Article 6 GDPR — Lawfulness of Processing(gdpr-info.eu)
- GDPR Chapter 3 — Rights of the Data Subject(gdpr-info.eu)
- Regulation (EU) 2025/2518 - GDPR Procedural Regulation (EUR-Lex)(eur-lex.europa.eu).gov
- Regulation (EU) 2026/1744 - Digital Omnibus on AI (EUR-Lex)(eur-lex.europa.eu).gov
- Regulation (EU) 2024/1689 - EU Artificial Intelligence Act (EUR-Lex)(eur-lex.europa.eu).gov
- COM(2025) 837 - Digital Omnibus proposal, data limb (EUR-Lex)(eur-lex.europa.eu).gov
- European Parliament Legislative Observatory - procedure 2025/0360(COD)(oeil.europarl.europa.eu).gov
- Omnibus IV provisional agreement PE790.249, 26 June 2026 (European Parliament)(europarl.europa.eu).gov
- European Parliament Legislative Observatory - procedure 2025/0130(COD), Omnibus IV(oeil.europarl.europa.eu).gov
- Irish DPC - TikTok EUR 530 million decision and corrective measures(dataprotection.ie).gov
- Irish DPC - index of court judgments in DPC proceedings(dataprotection.ie).gov
- Ireland - Data Protection Act 2018, section 31 (digital age of consent)(irishstatutebook.ie).gov
- Spain - Ley Organica 3/2018, Article 7 (consent of minors)(boe.es).gov
- DLA Piper - GDPR Fines and Data Breach Survey, January 2026(dlapiper.com)
- CMS GDPR Enforcement Tracker - statistics(enforcementtracker.com)